Skip to content

Security

Clear control over sensitive work.

Protect payment records, customer context, and team decisions with organization access controls, private evidence, human review, and a traceable case history.

Access and connected accounts

Your workspace, your team, your records.

Access is checked against the organization each record belongs to.

Organization boundaries

Cases, evidence, drafts, invoices, and activity records belong to one organization. Membership checks apply before workspace data is returned.

Clear responsibilities

Owners manage the workspace and billing. Analysts prepare cases. Owners and reviewers approve dispute responses.

Verified accounts

Members use their own accounts and verify their email address before accessing organization data.

Connect Stripe through the Stripe App without sharing your Stripe password. Connected-account credentials are stored securely and available only to services that need them. Resolvely requests permissions to show cases, submit approved evidence, and confirm recovered amounts. Funds stay with your payment provider; Resolvely does not store card numbers or hold customer funds.

Evidence, review, and history

Supporting evidence. Human decisions.

Keep the records, approval, and resulting action connected.

Private evidence and temporary links

Files are stored privately. Authorized members receive short-lived upload and download links after access checks; there is no public file library.

Approval before submission

An Owner or reviewer must approve every dispute response. Unsupported claims must be corrected first, and duplicate-submission safeguards protect retries.

Recorded audit trail

Evidence changes, drafts, approvals, submissions, and billing events are recorded in an append-only audit log.

AI helps prepare the response; your team approves it.

Drafting uses case details and supporting evidence, including text extracted from documents. Claims cite their sources, and those citations are checked before approval.

AI processing takes place in the United States through Amazon Bedrock. Resolvely and Bedrock do not use drafting content to train their models. A person reviews and approves the final wording.

Data protection

Encrypted records and protected sessions.

Resolvely operates across multiple AWS regions in the United States, with encryption in transit and at rest.

AES-256 encryption at rest

Case records and evidence files use AES-256 encryption. Database encryption also covers automated backups and snapshots.

TLS and secure sessions

HTTPS connections use TLS 1.2 or later. Secure session cookies protect sign-in, and payment-provider credentials are kept out of the browser.

Sensitive logs redacted

Operational logs redact authorization credentials, provider signatures, and request bodies.

The privacy policy explains data use, retention, essential cookies, and the service providers involved.

Scope and disclosure

Know the requirements before sharing data.

Security reviews and data requirements

Resolvely has not completed a SOC 2 audit. Contact us for a security review. Deletion requests go to privacy@resolvely.com; a custom automated retention schedule is not currently offered.

The service is not designed for protected health information. Do not upload PHI or regulated data that requires a business associate agreement.

Responsible disclosure

Report a security issue to legal@resolvely.com with the details and steps to reproduce. We acknowledge reports within 2 business days, keep you informed while we investigate, and do not pursue good-faith researchers who avoid accessing other customers' data.